METHOD FOR VERIFYING AND CONTROLLING OUTGOING DATA TRAFFIC AND COMMUNICATION SYSTEM FROM AN IP-ENABLED HOME NETWORK END DEVICE

DE502021008366D1Active Publication Date: 2025-09-11DEUTSCHE TELEKOM AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502021008366
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-22
Publication Date
2025-09-11
Estimated Expiration
2041-04-22

AI Technical Summary

Technical Problem

The increasing number of smart home devices in private households poses a risk of DoS and DDoS attacks, as they can be manipulated into botnets, overwhelming servers with requests and rendering them inoperable.

Method used

A method and communication system that categorize smart home devices into defined types, assign usage profiles, and monitor/control data traffic to prevent excessive requests, using an IP-capable home network router to limit data communication based on device type.

Benefits of technology

Significantly reduces the impact of DoS/DDoS attacks by preventing smart home devices from overwhelming servers, ensuring network devices remain operational.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for checking and controlling data traffic containing IP packets originating from an IP-capable home network terminal, as well as to a communication system which is particularly designed for checking and controlling such data traffic.

[0002] As the number of smart home devices in private households increases, so does the risk of DoS attacks, also called denial of service attacks, or DDoS attacks, also called distributed denial of service attacks, carried out by infected smart home devices.

[0003] The general goal of DoS attacks is to reduce or prevent the availability of a target, such as an internet service, an internet server, or other network device, by sending a large number of requests, making it impossible to respond to legitimate requests. Originally, such DoS attacks involved infecting a single source device, which then sent a large number of requests to the attacked target. In contrast, so-called DDoS attacks involve infecting or infecting multiple source devices, making their attacks on targets more difficult to prevent.

[0004] In recent years, smart home devices have been increasingly manipulated and added to so-called botnets due to their high number, global distribution, and often existing security vulnerabilities. A botnet is a collection of devices controlled and managed by an attacker without the owners' knowledge. One example of a large botnet consisting of IoT (Internet of Things) smart home devices is the Mirai botnet.

[0005] There are various types of DoS or DDoS attacks. These can be classified based on the ISO / OSI model. Some typical attacks are listed below: HTTP GET FOOD attacks at the application layer: In these attacks, an infected source sends a large number of HTTP GET Hypertext Transfer Protocol messages to a web server. The server becomes so overwhelmed by responding to the requests that it can no longer respond to legitimate requests.

[0006] SYN Flood attacks at the transport protocol layer: In this case, an infected source sends a large number of TCP SYN messages to disrupt server connection processing. The servers are overloaded, particularly by storing TCP sessions.

[0007] Volume-based attacks: These involve transmitting a large number of UDP (User Datagram Protocol) messages or ICMP (Internet Control Message Protocol) messages, for example, to a server, so that it becomes overloaded and can no longer receive or respond to legitimate requests.

[0008] It should be noted that smart home devices, as components of a botnet, can carry out all of the above-mentioned DoS or DDoS attacks, depending on the device type.

[0009] US 2020 / 0204580 A1 discloses a method and a system that can defend against DDoS attacks, also known as distributed denial-of-service attacks, using a blockchain.

[0010] US 2020 / 0067974 A1 discloses a local network router that performs a cooperative defense against DDoS attacks originating from a local network, also known as distributed denial-of-service attacks.

[0011] The present invention is therefore based on the object of providing a method for checking and controlling data traffic originating from an IP-capable home network terminal, and a communication system with which it is possible to significantly reduce the effects of a DoS or DDoS attack originating from a home network. In particular, the method and the communication system can ensure that, after an infection, IP-capable home network terminals can at least be prevented from conducting DDoS or DoS attacks on servers accessible, for example, via the Internet, to the extent that the servers are flooded in an uncontrolled manner.

[0012] A core idea of the invention can be seen in the legitimate monitoring and control of data traffic from IP-capable home network end devices that are connected to an IP-capable home network router via a home network, and controlling or, if necessary, limiting it. For this purpose, the smart home devices that can be used in a home network are categorized, i.e., divided into defined device types, such as smoke detectors, motion detectors, or surveillance cameras. A home network end device connected to the home network is assigned corresponding device type information. Typically, the device type information is stored in the respective home network end device and transmitted, for example, when a connection is initially established to the home network router. A predefined usage profile, hereinafter also referred to as a home network end device-dependent data communication usage profile, is created for each defined device type.The data communication usage profile defines, in particular, the regular function or the intended framework within which the corresponding device type can conduct data communication. Multiple home network terminal-dependent data communication usage profiles can be stored in the home network router. The home network router is preferably configured to automatically recognize the device type of the respective home network terminal based on device type information received from a home network terminal and to assign the respective home network terminal-dependent data communication usage profile to this home network terminal. Based on the home network terminal-dependent data communication usage profile, the home network router can monitor and, if necessary, limit the data traffic outgoing from the associated home network terminal.

[0013] In this way, the home network router can, in particular, prevent a home network device that is, for example, part of a botnet from generating massive request messages that could, for example, overload a target Internet server and thus render it inoperable.

[0014] IP-enabled home network devices are also referred to as smart home devices.

[0015] It should be noted at this point that the invention cannot prevent the malicious integration of a smart home device into a botnet; however, the effects of such an attack can be significantly reduced thanks to the invention, so that, ideally, it neither leads to a failure nor to an overload of a network device.

[0016] The above-mentioned technical problem is solved, on the one hand, by the method steps of claim 1 and by the features of claim 9.

[0017] The invention is explained in more detail below using several exemplary embodiments in conjunction with the accompanying drawings. In these drawings: Figure 1 shows an exemplary communication system in which the invention is implemented, Figure 2 shows an exemplary schematic functional sequence of the Figure 1 shown communication system for automatically detecting a device type, for automatically assigning a data communication usage profile and for reducing the data traffic emanating from a home network terminal, and Figure 3 shows an exemplary sequence of an automatic assignment of a data communication usage profile and an exemplary manual assignment of a data communication usage profile.

[0018] Figure 1shows an exemplary communication system 10, which can be installed at least partially, for example, in a living space or in a residential building. The communication system 10 has, for example, a plurality of preferably IP-capable home network terminals, hereinafter also referred to as smart home devices, which can be connected to at least one IP-capable home network router 50 via a home network 40. In this way, the IP-capable home network terminals can be given access to an external IP communication network 60. The external communication network 60 can be the Internet.

[0019] Merely as examples, Figure 1Three IP-capable home network terminals 20, 30, and 70 are shown, which can be connected to the IP-capable router 50 via the home network 40. It should be noted at this point that an IP-capable home network terminal is preferably a terminal configured to transmit IP packets via the router 50 to the external IP communications network 60. The IP-capable home network terminals 20, 30, and 70 can be, for example, household appliances, such as light sources and blinds, entertainment electronics devices, and in particular IoT home network terminals, such as smoke detectors, motion detectors, door contacts, thermostats, or surveillance cameras. The home network terminals 20, 30, and 70 can communicate with the IP-capable home network router 50 via wireless or wired connections of the home network 40.Preferably, the home network 40 can be, for example, a WLAN (Wireless Local Area Network) or a wired LAN (Local Area Network). Accordingly, each of the home network terminals 20, 30, and 70 can have a wired or wireless communication interface 22, 32, or 72, respectively, in order to be able to communicate with the router 50 via the home network 40. Similarly, the IP-capable home network router 50 has a wireless or wired communication interface 54 for connecting to the home network 40. In the present example, it is assumed that the home network 40 is a WLAN network, and the communication interfaces 22, 32, 72, and 54 are designed as wireless communication interfaces.

[0020] It should be noted that the communication interfaces 22, 32, and 72 of the home network terminals 20, 30, and 70 can each be part of a network adapter, each of which is assigned a globally unique MAC (Medium Access Control) address in a known manner, which is preferably stored as a hardware address in the respective network adapter of the home network terminal 20, 30, or 70. In the present example, it is assumed that the home network terminals 20 and 70 are, for example, smoke detectors, while the home network terminal 30 can be a surveillance camera.

[0021] In order to be able to forward data traffic provided by the home network terminals 20, 30, and 70 via the external IP communications network 60, for example to a destination server, the IP-capable home network router 50 has a further communications interface 53, via which a connection to the Internet 60 can be established. It should be noted that the IP-capable home network router 50 can be connected to the Internet 60 via a wireless or wired access network 80. Depending on the access network 80, the communications interface 53 can be a wired interface, such as a DSL communications interface, or a wireless communications interface, which can be designed according to a mobile communications standard, such as the LTE, UMTS, or 5G standard.

[0022] The home network terminals 20, 30, and 70 each have a control device 21, 31, or 71, which can preferably be embodied as a microprocessor or microcontroller. The control devices 21, 31, and 71 are each particularly designed to control and monitor the operation of the respective home network terminal. For this purpose, an operating system or firmware can preferably be stored in each of the home network terminals 20, 30, and 70, which can be stored in a storage device 23 of the home network terminal 20, in a storage device 33 of the home network terminal 30, and in a storage device 73 of the home network terminal 70.In addition, at least one communication protocol, such as a communication protocol for automatically assigning network configuration data, for example the DHCP (Dynamic Host Configuration Protocol), and / or the TCP / IP protocol, and / or an Ethernet protocol and / or the SIP (Session Initiation Protocol), and / or the UDP and / or the ICMP, can be stored in the memory devices 23, 33 and 73, which can be executed by the respective control device 21, 31 or 71.

[0023] It should be noted that the home network terminals 20, 30, and 70 can be assigned to predefined categories or device types. For example, in order to assign the two home network terminals 20 and 30 to a specific category, predetermined device type information is stored in each of the home network terminals 20 and 30, which designates a predefined device type. According to the present example, device type information that identifies the home network terminal 20 as a smoke detector is stored in the storage device 23. Device type information that identifies the home network terminal 30 as a surveillance camera is stored in the storage device 33. As will be explained in more detail below, the device type information stored in the home network terminals 20 and 30 is required by the home network router 50 in order to be able to assign a home network terminal type-dependent data communication usage profile to the home network terminals 20 and 30.

[0024] Similar to home network terminals, the home network router 50 has a control device 51, which can be embodied as a microcontroller or microprocessor. Furthermore, the router 50 has a memory device 52 in which an operating system or firmware can be stored. The control device 51 is preferably designed to monitor and control the operation of the home network router 50 using the operating system or firmware. Furthermore, at least one communication protocol, such as a communication protocol for automatically assigning network configuration data, for example, the DHCP (Dynamic Host Configuration Protocol), and / or the TCP / IP protocol, and / or an Ethernet protocol, and / or the SIP (Session Initiation Protocol), and / or the UDP and / or the ICMP, can be stored in the memory device 52, which can be executed by the control device 51.

[0025] The memory device 52 of the home network router 50 can store several different IP addresses, which are preferably private IP addresses, which are freely assigned, for example, from the private IP address ranges defined in RFC 1918. It should already be mentioned at this point that the IP addresses can be assigned to the home network terminal devices 20, 30, and 70 in a manner to be described later. Furthermore, the memory device 52 preferably stores several predefined data communication usage profiles dependent on the home network terminal device type, each of which defines, in particular, the framework or scope of data communication that is specified for a specific device type and which may be performed by the respective device type.

[0026] For a home network terminal type "smoke detector," the corresponding data communication usage profile A can contain the following rules or data traffic-related information: Maximum number of concurrent TCP connections: This number represents the upper limit for the number of simultaneous TCP connections a smoke detector can establish and maintain. In this example, the maximum number is 5. Permitted protocols: These are the protocols that a smoke detector is permitted to use. These include, for example, TCP (Transmission Control Protocol), UDP (User Datagram Protocol), and SIP (Session Initiation Protocol).

[0027] For a home network device type "surveillance camera," the corresponding data communication usage profile B can contain the following rules or data traffic-related information: Data rate: This is preferably a maximum threshold up to which a surveillance camera is allowed to send data. For example, the data rate is 10 Mbps. Maximum number of parallel TCP connections: e.g., 10. Permitted protocols: TCP, UDP, SIP, RTP (Realtime Transmission Protocol), HTTP.

[0028] In addition, at least one data communication usage profile could also specify, for example, the maximum number of request messages that the respective device type may transmit, preferably simultaneously or during a specified time interval. Typical request messages include SYN messages, which are used to establish TCP connections, and HTTP GET request messages, which are required to request web content.

[0029] The following describes the functionality of the Figure 1 The communication system 10 shown as an example is explained in more detail. In particular, an exemplary mode of operation of the communication system 10 for checking and controlling or limiting IP-based data traffic originating from the IP-capable home network terminal 20 and / or from the home network 30, which data traffic contains, in particular, IP packets, is described.

[0030] In order for the home network terminals 20, 30, and 70 to participate in network communication within the home network 40 and on the Internet 60, each of the home network terminals requires an IP address. An IP address is preferably assigned to the respective home network terminals 20, 30, and 70 by the home network router 50. The assignment can be performed in a known manner using a communication protocol for the automatic assignment of network configuration data, for example, the aforementioned DHCP protocol.

[0031] First, in connection with the home network terminal 20, it will be explained by way of example how the home network router 50 automatically assigns an IP address and one of the home network terminal type-dependent data communication usage profiles stored in the storage device 52 to the home network terminal 20. Assume that at least the home network terminal type-dependent data communication usage profile A defined for the device type "smoke detector" and the home network terminal type-dependent data communication usage profile B defined for the device type "surveillance camera" are stored in the storage device 52. Furthermore, as already mentioned above, the MAC address X and the device type information A, which indicates a smoke detector, are stored in the home network terminal 20, and the MAC address Y and the device type information B, which indicates a surveillance camera, are stored in the home network terminal 30. This is described in the Figure 2 and 3 shown schematically.

[0032] Before the home network terminal 20 can transmit IP-based data traffic via the home network router 50 to the Internet 60, the home network terminal 20 first generates a request message, for example, a DHCP Discover message. The home network terminal 20 is particularly configured to include not only the MAC address X, as is usual, but also the device type information A stored in the storage device 23 in the DHCP Discover message and to transmit it via the home network 40 to the home network router 50. It is conceivable that a corresponding DHCP Discover message is automatically generated and transmitted by the home network terminal 20 after power-on. In a manner known per se, the control device 51 of the home network router 50 is designed to cause the home network router 50 to assign an IP address to the home network terminal 20 in response to the received DHCP Discover message.For this purpose, the control device 51 preferably reads the MAC address X from the received DHCP Discover message and assigns the MAC address X to one of the IP addresses stored in the memory device 52, for example the IP address IP_1. The control device 51 of the home network router 50 is preferably designed to generate a so-called DHCP Offer message in response to the DHCP Discover message received from the home network terminal 20 and to transmit this message together with the IP address IP_1 previously assigned to the home network terminal 20 to the home network terminal 20 via the home network 40. The IP address IP_1 received with the DHCP Offer message is then stored, for example, in the memory device 23 of the home network terminal 20 and used for subsequent communication. This is also shown in FIG. Figure 2 shown schematically.

[0033] Furthermore, the control device 51 is configured to cause the home network router 50 to read the device type information A from the received DHCP Discover message, which contains the information that the home network terminal 20 is a smoke detector. Depending on the read device type information A, the control device 51 causes the home network router 50 to assign the data communication usage profile A stored in the storage device 52 to the home network terminal 20. Subsequently, the control device 51 causes the home network router 50 to store linking information in the storage device 52, which links the MAC address X of the home network terminal 20 and the data communication usage profile A, as well as preferably the IP address IP_1, which were previously assigned to the home network terminal 20.In addition, the MAC address X assigned to the home network terminal 20 is also stored in the memory device 52 of the home network router 50. It should be noted at this point that the home network terminal 20 generally does not know which data communication usage profile has been assigned to it. In other words, the home network router 50 preferably does not transmit the data communication usage profile assigned to the home network terminal 20 to the terminal 20.

[0034] In a similar or identical manner, the home network router 50 can automatically assign an IP address IP_2 and one of the home network terminal type-dependent data communication usage profiles stored in the memory device 52 to the home network terminal 30, in the present example the data communication usage profile B. This is shown schematically in Figure 3 shown.

[0035] Before the home network terminal 30 can transmit IP-based data traffic via the home network router 50 to the Internet 60, the home network terminal 30 first generates a request message, for example, a DHCP Discover message. The home network terminal 30 is particularly configured to include not only the MAC address Y, as is usual, but also the device type information B stored in the memory device 23 in the DHCP Discover message and to transmit it via the home network 40 to the home network router 50. It is conceivable that a corresponding DHCP Discover message is automatically generated and transmitted by the home network terminal 30 after power-on. In a manner known per se, the control device 51 of the home network router 50 is designed to cause the home network router 50 to assign an IP address to the home network terminal 30 in response to the received DHCP Discover message.For this purpose, the control device 51 preferably reads the MAC address Y from the received DHCP Discover message and assigns the MAC address Y to one of the IP addresses stored in the memory device 52, for example, the IP address IP_2. The control device 51 of the home network router 50 is preferably designed to generate a so-called DHCP Offer message in response to the DHCP Discover message received from the home network terminal 30 and to transmit this message, together with the IP address IP_2 previously assigned to the home network terminal 30, to the home network terminal 30 via the home network 40. The IP address IP_2 received with the DHCP Offer message is then stored, for example, in the memory device 33 of the home network terminal 30 and used for subsequent communication.

[0036] Furthermore, the control device 51 is configured to cause the home network router 50 to read the device type information B from the received DHCP Discover message, which contains the information that the home network terminal 30 is a smoke detector. Depending on the read device type information B, the control device 51 causes the home network router 50 to assign the data communication usage profile B stored in the storage device 52 to the home network terminal 30. Subsequently, the control device 51 causes the home network router 50 to store linking information in the storage device 52, which links the MAC address Y of the home network terminal 30 and the data communication usage profile B, as well as preferably the IP address IP_2, which were previously assigned to the home network terminal 30.In addition, the MAC address Y assigned to the home network terminal 30 is also stored in the memory device 52 of the home network router 50. It should be noted at this point that the home network terminal 30 generally does not know which data communication usage profile has been assigned to it. In other words, the home network router 50 preferably does not transmit the data communication usage profile assigned to the home network terminal 30 to the terminal 30.

[0037] It should be noted at this point that the data traffic-related information contained in the data communication usage profile A is used in the home network router 50 to limit the IP-based data traffic outgoing from the home network terminal 20 to the corresponding threshold, namely five parallel TCP connections. This prevents the home network terminal, should it have been integrated into a botnet through an attack, from transmitting limited IP-based data traffic to the Internet, thus preventing the failure of Internet servers or the overloading of Internet target servers.

[0038] Using the exemplary data communication usage profile A, which, as explained above, has been assigned to the home network terminal 20 by the home network router 50, the functionality of the home network router 50 to check the data traffic outgoing from the home network terminal 20 for compliance with the data communication usage profile A and to control or limit it depending on the result of the check carried out is explained in more detail.

[0039] Now assume that the home network terminal 20 has already initiated the establishment of five parallel TCP connections via the home network router 50 to the Internet 60, as described in Figure 2This communication status can be monitored or verified by the home network router 50, for example, by counting the number of TCP SYN messages generated by the home network terminal 20 and forwarded via the home network router 50 to establish corresponding independent TCP connections. It should be noted that as long as the number of TCP SYN messages generated by the home network terminal 20 so far falls below the threshold of 5 specified in data communication usage profile A, the home network router 50 allows further TCP SYN connection establishment messages to pass through.

[0040] However, as assumed above, five parallel TCP connections have already been established. Now let us further assume that home network device 20, as in Figure 2can be seen, two further TCP SYN messages are generated as connection setup messages and transmitted via the home network 40 to the home network router 50. The control device 51 is designed to detect that five parallel TCP connections have already been established by the home network terminal 20 and are currently still in operation. In response to the data communication usage profile A assigned to the home network terminal 20 and the two further connection setup messages, the home network router 50 blocks all further connection setup messages that exceed the defined threshold value of 5. Only when at least one of the five existing TCP connections is terminated, for example by the terminal 20, can new connection setup messages, i.e. TCP SYN messages, be generated by the home network terminal 20, which the home network router 50 allows through. This communication behavior is also schematically shown in Figure 2can be seen, for example, whereby the TCP connection 5 is terminated and consequently another TCP connection 8 can be established. In this way, for example, it can be prevented that the home network terminal 20 can uncontrollably flood the Internet 60 with data via a large number of parallel TCP connections as a result of a DDoS attack.

[0041] Now, using the exemplary data communication usage profile B, which, as explained above, has been assigned to the home network terminal 30 by the home network router 50, the functionality of the home network router 50 to check the data traffic outgoing from the home network terminal 30 for compliance with the data communication usage profile B and to control or limit it depending on the result of the check carried out will be explained in more detail.

[0042] As explained above, the data communication usage profile B assigned to the device type "surveillance camera" and thus to the home network terminal 30 contains, for example, data traffic information that specifies the maximum data rate at which the home network terminal 30, i.e., a surveillance camera, is permitted to transmit IP packets. In the example considered here, the maximum data rate is 10 Mbps.

[0043] Let us now assume that the home network terminal 30 generates an outgoing data stream comprising IP packets, wherein each IP packet of the data stream contains the IP address IP_2 previously assigned to the home network terminal 30 by the home network router 50 and the MAC address Y. The home network router 50 is designed to receive the data traffic outgoing from the home network terminal 30 and, based on the IP packets contained therein, to check compliance with the data communication usage profile B assigned to the home network terminal 30 and, depending on the result of the check carried out, to control or limit the data traffic outgoing from the home network terminal 30. Advantageously, the control device 51 is designed to cause the home network router 50 to monitor or limit the data rate of the data traffic outgoing from the home network terminal 30.to check for compliance with the specified data rate, for example by counting the number of IP packets of outgoing data traffic per unit of time. Since the number of bits contained in an IP packet is known, the control device 51 can monitor the data rate. If the control device 51 determines that the data rate specified in the data communication usage profile B, for example 10 Mbps, is exceeded by the home network terminal 30, the home network router 50 automatically limits the outgoing data traffic from the home network terminal 30 to the permissible data rate. In this way, it can be prevented, for example, that the home network terminal 30 floods the Internet 60 with data in an uncontrolled manner as a result of a DDoS attack.

[0044] Since, for example, the data communication usage profile B assigned to the home network terminal 30 contains at least one communication protocol to be used as additional data traffic information—in the present example, these are the communication protocols TCP and UDP—the control device 51 of the home network router 50 is further configured to check, based on the IP packets contained in the data traffic outgoing from the home network terminal 30, whether a permissible communication protocol is being used. This is possible because the IP packets generally also contain the communication protocols used by the home network terminal 30.

[0045] Conceivable in this context is a DDoS attack on the home network terminal 30, which causes the home network terminal 30 to transmit request messages according to the Post Office Protocol (POP) to a specific email server in order to retrieve alleged emails from there. As a result of this attack, the home network terminal 30 would, for example, be caused to transmit a large number of such POP request messages to the email server, so that the latter can no longer process legitimate POP-based request messages. Thanks to the invention, however, the home network router 50 is able to check the outgoing IP packets from the home network terminal 30 based on the data communication usage profile B assigned to the home network terminal 30 to determine whether they were generated according to an approved communication protocol.If this is not the case, the home network router 50 prevents the forwarding of these IP packets generated by the home network terminal device 30, thereby preventing a failure or overload of the respective email server.

[0046] Now, an exemplary case will be considered in which a home network terminal, for example, home network terminal 70, is not configured to store device type information and transmit it in a request message, in particular in a DHCP Discover message, to home network router 50. So that home network router 50 can nevertheless monitor and, if necessary, limit data traffic outgoing from home network terminal 70, a user of home network 40 must manually assign a home network terminal type-dependent data communication usage profile, in the present example, data communication usage profile A, to home network terminal 70 on home network router 50.

[0047] An exemplary scenario provides that, after switching on, the home network terminal 70 generates, for example, a DHCP Discover message and transmits the MAC address Z assigned to the communication interface 72 to the home network router 50 in this DHCP Discover message. The home network router 50 is configured, in a manner known per se, to assign an IP address, for example the IP address IP_3, to the home network terminal 70 in response to the received DHCP Discover message and to transmit this address in a DHCP Offer message via the home network 40 to the home network terminal 70.Furthermore, it is assumed that the user now manually assigns the data communication usage profile A to the home network terminal 70 in the home network router 50, for example by entering linking information on the home network router 50 that establishes a link between the MAC address Z and the data communication usage profile A and, if applicable, with the IP address IP_3. The home network router 50 then stores the MAC address Z of the home network terminal 70 in the storage device 52 together with the linking information created by the user. In this way, the home network router 50 is enabled to check IP packets originating from the home network terminal 70, which contain the MAC address Z in addition to the IP address IP_3, for compliance with the data communication usage profile A, which was previously manually assigned to the home network terminal 50 in the home network router 50. These steps are shown schematically in FIG. Figure 3In this way, the home network router 50 can prevent, in the manner explained above, the home network terminal device 70 from flooding the Internet 60 with data in an uncontrolled manner as a result of a DDoS attack, for example.

[0048] Below, at least some of the exemplary aspects are summarized again.

[0049] According to one exemplary aspect, a method is provided which can be used, for example, to check and control data traffic containing IP packets originating from an IP-capable home network terminal 20, wherein the home network terminal 20 is connectable via a home network 40 to an IP-capable home network router 50 having an interface 53 for communication with an external IP communications network 60, 80. The method can, for example, comprise at least some of the following method steps: a) storing, in the IP-enabled home network router (50), a plurality of home network terminal type-dependent data communication usage profiles; b) storing, in the home network terminal 20, device type information and a MAC address assigned to the home network terminal 20; c) transmitting, from the home network terminal 20, using a communication protocol for automatically assigning network configuration data, a request message via the home network 40 to the IP-enabled home network router 50, wherein the request message contains the MAC address and device type information stored in step b); d) assigning, by the home network router 50, to the home network terminal 20, in response to the received request message, an IP address and, depending on the device type information, one of the data communication usage profiles stored in step a);e) storing, in the home network router (50), the MAC address of the home network terminal 20 and assignment information which links the data communication usage profile assigned to the home network terminal 20 in step d) with the MAC address of the home network terminal 20; f) transmitting, from the home network router 50, the IP address assigned to the home network terminal in step d) to the home network terminal 20; g) transmitting IP packets from the home network terminal 20 to the home network router 50; h) checking, by the home network router 50, the data traffic outgoing from the home network terminal 20 based on the IP packets received in step g) for compliance with the data communication usage profile assigned to the home network terminal 20 in step d); and i) controlling, by the home network router 50, the data traffic outgoing from the home network terminal 20 depending on the result of the check performed in step h). ;

[0050] It should be noted that data traffic originating from an IP-capable home network terminal can be understood, in particular, as data traffic that is preferably intended for at least one server accessible via an external IP communications network. The data traffic preferably contains IP packets that may contain control or user data.

[0051] Advantageously, the home network terminal type-dependent data communication usage profiles stored in step a) can each contain at least one piece of data traffic-related information that can define a threshold value, wherein step i) includes limiting the data traffic outgoing from the home network terminal 20 to the respective threshold value by the home network router 50 in the event that the current data traffic exceeds the threshold value.

[0052] Advantageously, at least one of the home network terminal type-dependent data communication usage profiles stored in step a) can contain, as a first piece of data traffic-related information, the maximum number of TCP communication connections that may be established simultaneously by a home network terminal of the corresponding device type, wherein in step i) the establishment of a further TCP communication connection by the home network terminal 20 is prevented with the aid of the home network router 50 if it has been determined in step h) that the maximum number of parallel TCP communication connections that have been defined in the data communication usage profile assigned to the home network terminal 20 in step d) have already been established by the home network terminal 20 and the establishment of at least one further TCP communication connection has been initiated by the home network terminal 20.The final step, in which the home network terminal 20 initiates the establishment of at least one further TCP communication connection, is to be understood in particular as meaning that the home network terminal has generated at least one further connection establishment request message and transmitted it to the home network router. However, this connection establishment request message is discarded by the home network router or is no longer forwarded.

[0053] Advantageously, at least one of the home network terminal type-dependent data communication usage profiles stored in step a) can contain, as a second piece of data traffic-related information, the maximum data rate at which a home network terminal of the respective device type may transmit IP packets, wherein in step i) the forwarding of the data traffic outgoing from the home network terminal 20 is terminated with the aid of the home network router 50 or the current data rate for forwarding the data traffic outgoing from the home network terminal 20 is limited to the maximum data rate specified in the data communication usage profile assigned to the home network terminal 20 in step d), if it has been determined in step h) that the maximum data rate specified in the data communication usage profile assigned to the home network terminal 20 in step d) has been exceeded by the home network terminal 20.

[0054] Advantageously, at least one of the home network terminal type-dependent data communication usage profiles stored in step a) can contain at least one communication protocol to be used as a third data traffic-related information, wherein in step i) the forwarding of the data traffic outgoing from the home network terminal 20 is terminated or prevented with the aid of the home network router 50 if it has been determined in step h) that the communication protocol used by the home network terminal 20 does not match the communication protocol contained in the data communication usage profile assigned to the home network terminal 20 in step d).

[0055] Advantageously, the Dynamic Host Configuration Protocol (DHCP) can be used as a communication protocol for automatically assigning network configuration data, whereby the request message transmitted in step c) is a DHCP Discover message, and wherein in step f) the IP address is transmitted in a DHCP Offer message to the home network terminal 20 or 30.

[0056] Advantageously, at least some of the IP packets transmitted in step g) from the home network terminal 20 may each contain a request message, in particular an HTTP GET message or a TCP SYN connection setup message, wherein the home network terminal type-dependent data communication usage profiles stored in step a) each contain, as a fourth piece of data traffic-related information, the maximum number of request messages that a home network terminal of the respective device type may transmit simultaneously or during a predetermined period of time, wherein in step i) the forwarding of an IP packet outgoing from the home network terminal 20 containing a request message is prevented with the aid of the home network router 50 if it has been determined in step h) that the maximum number of request messages contained in the data communication usage profile assigned to the home network terminal 20 in step d) is exceeded.

[0057] Expediently, steps b) to i) can be repeated for at least one further home network terminal 30.

[0058] According to a further advantageous aspect, a communication system 10 is provided which may have at least some of the following features: a home network 40, at least one IP-capable home network terminal 20, 30, which can have a storage device 23 or 33 in which device type information and a communication protocol for the automatic assignment of network configuration data are stored, and a control device 21 or 31, wherein a MAC address is uniquely assigned to the at least one IP-capable home network terminal 20, 30, and at least one IP-capable home network router 50, which has a storage device 52, a control device 51 and an interface 53 for communication with an external IP communication network 60 and / or 80, wherein several home network terminal type-dependent data communication usage profiles are stored in the storage device 52 of the home network router 50, wherein the home network terminal 20, 30 and the home network router 50 are each designed for communication via the home network 40, wherein the control device 21,31 of the home network terminal 20 or 30 is configured to use the communication protocol for automatically assigning network configuration data to cause the home network terminal 20, 30 to transmit a request message via the home network 40 to the IP-capable home network router 50, wherein the request message contains the MAC address and device type information assigned to the home network terminal 20, 30, wherein the control device 51 of the home network router 50 can be configured to cause the home network router 50 to assign an IP address and, depending on the device type information, one of the stored data communication usage profiles to the at least one home network terminal 20, 30 in response to the received request message, the MAC address and a link between the MAC address of the home network terminal 20 in the memory device 52 of the home network router 50, 30 and the data communication usage profile,which have been assigned to the home network terminal (20, 30), and optionally the IP address assigned to the home network terminal 20, 30, and to transmit the IP address assigned to the home network terminal 20, 30 to the home network terminal 20, 30, wherein the home network terminal 20, 30 can further be designed to transmit outgoing data traffic containing IP packets to the home network router 50, wherein the home network router 50 can further be designed to receive the data traffic outgoing from the home network terminal 20, 30 and, based on the IP packets contained therein, to check for compliance with the data communication usage profile assigned to the home network terminal 20, 30, and to control the data traffic outgoing from the home network terminal 20, 30 depending on the result of the check carried out.

[0059] Advantageously, the home network terminal type-dependent data communication usage profiles stored in the memory device 52 of the home network router 50 can each contain at least one piece of data traffic-related information that defines a threshold value, wherein the home network router 50 can be configured to limit the data traffic outgoing from the home network terminal 20, 30 to the respective threshold value if the threshold value is exceeded.

[0060] Advantageously, the home network terminal type-dependent data communication usage profiles stored in the memory device 52 of the home network router 50 can each contain, as a first piece of data traffic information, the maximum number of TCP communication connections that may be established simultaneously by a home network terminal of the respective device type, wherein the home network router 50 can be designed to prevent the establishment of a further TCP communication connection by the home network terminal 20, 30 if the home network router 50, when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal 20, 30 based on the IP packets contained in the data traffic, has determined that the maximum number of parallel TCP communication connections that has been specified in the data communication usage profile assigned to the home network terminal 20, 30 can be established by the home network terminal 20,30 have already been established and the establishment of at least one further TCP communication connection has been initiated by the home network terminal 20, 30.

[0061] Advantageously, the home network terminal type-dependent data communication usage profile stored in the memory device 52 of the home network router 50 can each contain, as a second piece of data traffic information, the maximum data rate at which a home network terminal of the respective device type may transmit IP packets, wherein the home network router 50 can be designed to terminate the forwarding of the data traffic outgoing from the home network terminal 20, 30 or to limit the current data rate for forwarding the data traffic outgoing from the home network terminal 20, 30 to the maximum data rate that has been defined in the data communication usage profile assigned to the home network terminal 20, 30.to reduce if the home network router 50, when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal 20, 30 based on the IP packets contained in the data traffic, has determined that the maximum data rate specified in the data communication usage profile assigned to the home network terminal 20, 30 is exceeded by the home network terminal 20, 30.

[0062] Advantageously, the home network terminal type-dependent data communication usage profile stored in the memory device 52 of the home network router 50 can contain at least one communication protocol to be used as a third piece of data traffic information, wherein the home network router 50 can be designed to terminate or prevent the forwarding of the data traffic originating from the home network terminal (20, 30) if the home network router 50, when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal 20, 30 based on the IP packets contained in the data traffic, has determined that the communication protocol used by the home network terminal 20, 30 does not match the communication protocol contained in the data communication usage profile assigned to the home network terminal 20, 30.

[0063] Advantageously, the home network terminal 20, 30 and the home network router 50 can each be designed to execute the Dynamic Host Configuration Protocol (DHCP) as a communication protocol for automatically assigning network configuration data, wherein the home network device 20, 30 can be configured to generate a DHCP Discover message as a request message and to insert the stored device type information into the DHCP Discover message, wherein the home network router 50 can be configured to transmit the IP address assigned to the home network terminal 20, 30 in a DHCP Offer message to the home network terminal 20, 30).

[0064] The home network terminal 20, 30 can expediently be designed to generate an outgoing data traffic, which can comprise IP packets, each of which contains a request message, in particular an HTTP GET message or TCP SYN connection setup message, wherein at least one of the home network terminal type-dependent data communication usage profiles stored in the memory device 52 of the home network router 50 contains, as a fourth piece of data traffic-related information, the maximum number of request messages that a home network terminal 20, 30 of the respective device type may transmit simultaneously or during a predetermined period of time, wherein the home network router 50 can be designed to prevent the forwarding of an IP packet outgoing from the home network terminal 20, 30 that contains a request message if the home network router 50 has determined that the maximum number of request messages contained in the data communication usage profile assigned to the home network terminal (20, 30) has been exceeded by the home network terminal 20, 30.

[0065] It should be noted that each home network terminal device type-dependent data communication usage profile stored in the memory device 52 of the home network router 50 can also contain a corresponding device type-dependent first, and / or second, and / or third and / or fourth data traffic-related information.

Claims

1. A method for checking and controlling data traffic containing IP packets originating from an IP-capable home network terminal (20), wherein the home network terminal (20) is connectable via a home network (40) to an IP-capable home network router (50) which has an interface (53) for communication with an external IP communication network (60, 80), comprising the following method steps: a) storing, in the IP-enabled home network router (50), a plurality of home network terminal type-dependent data communication usage profiles; b) storing, in the IP-enabled home network terminal (20), a device type information and a MAC address associated with the home network terminal (20); c) transmitting, from the home network terminal (20), using a communication protocol for automatically assigning network configuration data, a request message via the home network (40) to the IP-enabled home network router (50), the request message including the MAC address and device type information stored in step b); d) assigning, by the home network router (50), to the home network terminal (20), in response to the received request message, an IP address and, depending on the device type information, one of the data communication usage profiles stored in step a); e) storing, in the home network router (50), the MAC address of the home network terminal (20) and association information linking the data communication usage profile associated with the home network terminal (20) in step d) to the MAC address of the home network terminal (20); f) transmitting, from the home network router (50), the IP address assigned to the home network terminal device in step d) to the home network terminal device (20); g) transmitting IP packets from the home network terminal (20) to the home network router (50); h) checking, by the home network router (50), the data traffic outgoing from the home network terminal (20) on the basis of the IP packets received in step g) for compliance with the data communication usage profile assigned to the home network terminal (20) in step d); and i) controlling, by the home network router (50), the data traffic outgoing from the home network terminal (20) depending on the result of the check performed in step h).

2. The method according to claim 1, characterized in that the home network terminal type-dependent data communication usage profiles stored in step a) each contain at least one piece of data traffic-related information which defines a threshold value, and in that step i) includes limiting the data traffic originating from the home network terminal (20) to the respective threshold value by the home network router (50).

3. The method according to claim 2, characterized in that at least one of the home network terminal type-dependent data communication usage profiles stored in step a) contains, as a first piece of data traffic-related information, the maximum number of TCP communication connections which may be established simultaneously by a home network terminal of the respective device type, and in that in step i), the establishment of a further TCP communication connection by the home network terminal (20) is prevented with the aid of the home network router (50) if it has been determined in step h) that the maximum number of parallel TCP communication connections, which has been defined in the data communication usage profile assigned to the home network terminal in step d), has already been established by the home network terminal (20) and the establishment of at least one further TCP communication connection has been initiated by the home network terminal (20).

4. The method according to claim 2 or 3, characterized in that at least one of the home network terminal type-dependent data communication usage profiles stored in step a) contains the maximum data rate at which a home network terminal of the respective device type may transmit IP packets as a second piece of data traffic-related information, and in that in step i), with the aid of the home network router (50), the forwarding of the data traffic originating from the home network terminal (20) is terminated or the current data rate for forwarding the data traffic originating from the home network terminal (20) is limited to the maximum data rate which has been defined in the data communication usage profile assigned to the home network terminal (20) in step d), if it has been determined in step h) that the home network terminal (20) has exceeded the maximum data rate defined in the data communication usage profile assigned to the home network terminal (20) in step d).

5. The method according to one of the preceding claims in conjunction with claim 2, characterized in that at least one of the home network terminal type-dependent data communication usage profiles stored in step a) contains at least one communication protocol to be used as a third piece of data traffic-related information, and in that in step i), with the aid of the home network router (50) the forwarding of the data traffic originating from the home network terminal (20) is terminated or prevented if it has been determined in step h) that the communication protocol used by the home network terminal (20) does not match the communication protocol contained in the data communication usage profile assigned to the home network terminal (20) in step d).

6. The method according to one of the preceding claims, characterized in that the Dynamic Host Configuration Protocol (DHCP) is used as the communication protocol for automatically assigning network configuration data, in that the request message transmitted in step c) is a DHCP discover message, and that in step f) the IP address is transmitted in a DHCP offer message to the home network terminal (20, 30).

7. The method according to one of the preceding claims in conjunction with claim 2, characterized in that at least some of the IP packets transmitted by the home network terminal (20) in step g) each contain a request message, in particular an HTTP GET message or a TCP SYN connection establishment message, in that at least one of the home network terminal type-dependent data communication usage profiles stored in step a) contains, as a fourth piece of data traffic-related information, the maximum number of request messages which a home network terminal of the respective device type may transmit simultaneously or during a predetermined period of time, and in that in step i), with the aid of the home network router (50) the forwarding of an IP packet containing a request message originating from the home network terminal (20) is prevented if it has been determined in step h) that the maximum number of request messages contained in the data communication usage profile assigned to the home network terminal (20) in step d) is exceeded.

8. The method according to one of the preceding claims, characterized in that steps b) to i) are repeated for at least one further home network terminal (30).

9. A communication system (10) comprising - a home network (40), - at least one IP-capable home network terminal (20, 30) having memory means (23, 33) in which device type information and a communication protocol for automatically assigning network configuration data are stored, and a control device (21, 31), wherein a MAC address is uniquely assigned to the IP-capable home network terminal (20, 30), and - at least one IP-capable home network router (50), which has a memory device (52), a control device (51) and an interface (53) for communication with an external IP communication network (60, 80), wherein a plurality of home network terminal type-dependent data communication usage profiles are stored in the memory device (52) of the home network router (50), wherein the home network terminal (20, 30) and the home network router (50) are each designed for communication via the home network (40), wherein the control device (21, 31) of the home network terminal (20, 30) is designed to cause the home network terminal (20, 30) to transmit a request message via the home network (40) to the IP-capable home network router (50) using the communication protocol for automatic assignment of network configuration data, the request message containing the MAC address assigned to the home network terminal (20, 30) and the device type information stored in the home network terminal (20, 30), wherein the control device (51) of the home network router (50) is designed to cause the home network router (50), - to assign an IP address and, depending on the device type information, one of the stored data communication usage profiles to the home network terminal (20, 30) in response to the received request message, - to store in the memory device (52) of the home network router (50) the MAC address and a link between the MAC address of the home network terminal (20, 30) and the data communication usage profile which have been assigned to the home network terminal (20, 30), and to transmit the IP address assigned to the home network terminal (20, 30) to the home network terminal (20, 30), wherein the home network terminal (20, 30) is further designed to transmit outgoing data traffic containing IP packets to the home network router (50), wherein the home network router (50) is further configured to receive the outgoing data traffic from the home network terminal (20, 30) and to check compliance with the data communication usage profile assigned to the home network terminal (20, 30) on the basis of the IP packets contained therein, and to control the outgoing data traffic from the home network terminal (20, 30) depending on the result of the check carried out.

10. The communication system according to claim 9, characterized in that the home network terminal type-dependent data communication usage profiles stored in the memory device (52) of the home network router (50) each contain at least one piece of data traffic-related information which defines a threshold value, and in that the home network router (50) is designed to limit the data traffic emanating from the home network terminal (20, 30) to the respective threshold value.

11. The communication system according to claim 10, characterized in that at least one of the home network terminal type-dependent data communication usage profiles stored in the memory device (52) of the home network router (50) contains, as a first piece of data traffic information, the maximum number of TCP communication connections which may be established simultaneously by a home network terminal of the respective device type, and in that the home network router (50) is designed to prevent the establishment of a further TCP communication connection by the home network terminal (20, 30) if the home network router (50), when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal (20, 30), has determined on the basis of the IP packets contained in the data traffic, that the maximum number of parallel TCP communication connections defined in the data communication usage profile assigned to the home network terminal (20, 30) has already been established by the home network terminal (20, 30) and the establishment of at least one further TCP communication connection has been initiated by the home network terminal (20, 30).

12. The communication system according to claim 10 or 11, characterized in that at least one of the home network terminal type-dependent data communication usage profiles stored in the memory device (52) of the home network router (50) contains, as a second piece of data traffic information, the maximum data rate at which a home network terminal of the respective device type may transmit IP packets, and in that the home network router (50) is designed to terminate the forwarding of the data traffic outgoing from the home network terminal (20, 30) or to limit the current data rate for forwarding the data traffic outgoing from the home network terminal (20, 30) to the maximum data rate which has been defined in the data communication usage profile assigned to the home network terminal (20, 30), if the home network router (50), when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal (20, 30), has determined on the basis of the IP packets contained in the data traffic that the maximum data rate defined in the data communication usage profile assigned to the home network terminal (20, 30) has been exceeded by the home network terminal (20, 30).

13. The communication system according to any one of claims 9 to 12, characterized in that the home network terminal type-dependent data communication usage profiles stored in the memory device (52) of the home network router (50) each contain at least one communication protocol to be used as a third piece of data traffic information, and in that the home network router (50) is designed to terminate or prevent the forwarding of the data traffic originating from the home network terminal (20, 30) if the home network router (50), when checking the data traffic for compliance with the data communication usage profile assigned to the home network terminal (20, 30) has determined, on the basis of the IP packets contained in the data traffic, that the communication protocol used by the home network terminal (20, 30) does not match the communication protocol contained in the data communication usage profile assigned to the home network terminal (20, 30).

14. The communication system according to any one of claims 9 to 13, characterized in that the home network terminal (20, 30) and the home network router (50) are each designed to execute the Dynamic Host Configuration Protocol (DHCP) as the communication protocol for automatically assigning network configuration data, in that the home network device (20, 30) is designed to generate a DHCP discover message as a request message and to insert the stored device type information into the DHCP discover message, and in that the home network router (50) is designed to transmit the IP address assigned to the home network terminal device (20, 30) in a DHCP offer message to the home network terminal device (20, 30).

15. The communication system according to any one of claims 9 to 14, characterized in that the home network terminal (20, 30) is configured to generate an outgoing data traffic which may comprise IP packets each containing a request message, in particular an HTTP GET message or TCP SYN connection establishment messages, that at least one of the home network terminal type-dependent data communication usage profiles stored in the memory device (52) of the home network router (50) contains, as a fourth piece of data traffic-related information, the maximum number of request messages which a home network terminal (20, 30) of the respective device type may transmit simultaneously or during a predetermined period of time, and in that the home network router (50) is designed to prevent the forwarding of an IP packet containing a request message originating from the home network terminal (20, 30) if the home network router (50) has determined that the maximum number of request messages contained in the data communication usage profile assigned to the home network terminal (20, 30) is exceeded by the home network terminal (20, 30).